Operational resilience has entered a new phase: organisations are no longer being judged solely on their resilience frameworks, but on their ability to demonstrate that they can recover from disruption. In this blog, Tom Infante explores how regulatory expectations are evolving, why recoverability is becoming the defining measure of operational resilience, and the practical steps organisations can take to strengthen recovery, governance and operational capability in an increasingly complex threat landscape.
When I wrote about operational resilience in 2025, the message was that resilience was no longer about responding to disruption, it was about designing for it.
The FCA's 31 March 2025 implementation deadline marked the end of one phase of operational resilience and the beginning of another. The focus has shifted from implementing resilience frameworks to demonstrating that they work in practice.
Regulators are no longer asking whether firms have documented plans. They are asking whether those plans have been tested, whether recovery can be demonstrated under realistic conditions, and whether organisations can provide evidence that critical business services will remain within agreed impact tolerances.
This represents an important shift. Operational resilience is moving beyond a compliance exercise and becoming an operational capability. Increasingly, resilience is measured not by the quality of a firm's documentation, but by the confidence with which it can recover. The organisations making the greatest progress are those treating operational resilience as a business capability rather than a regulatory obligation.
The events of the past year have reinforced this change. Major cloud outages, increasingly sophisticated ransomware attacks and the FCA's first observations on firms' resilience self-assessments all point to the same conclusion: organisations must be able to demonstrate recoverability, not simply describe it.
Recovery has become the operational resilience KPI
Perhaps the biggest change is that recovery has become the defining measure of operational resilience.
For many years, organisations invested heavily in preventing disruption. Prevention remains essential, but today's threat landscape assumes that incidents will occur. The differentiator is no longer whether an organisation experiences disruption, but how quickly and confidently it restores critical services.
This shift changes the conversation in the boardroom. Recovery time, recovery confidence and recovery evidence are becoming the metrics that matter most.
Ransomware exposes whether resilience is real
No scenario tests operational resilience more effectively than ransomware.
According to Sophos' State of Ransomware in Financial Services 2025, 59% of attacks against financial services organisations resulted in encrypted data, while the median ransom demand increased by 50% to £2.7 million. The average recovery cost, excluding any ransom payment, reached £1.5 million.
More revealing than the financial impact is how organisations are recovering. The proportion restoring operations from backups has fallen to a four-year low of 44%, and for the first time more organisations reported paying a ransom than recovering from backup.
This highlights a significant challenge. Modern attackers increasingly target backup environments alongside production systems, while many organisations discover during an incident that recovery processes have never been fully validated under realistic conditions.
Leading organisations are investing in immutable backups, isolated recovery environments and secure data vaults. More importantly, they are routinely testing these capabilities to prove they can restore critical services within agreed recovery objectives.
That emphasis on demonstrable recovery is reflected in the FCA's own observations, which identify investment in recovery capability, not simply preventative controls, as an area of increasing maturity across the sector.
From prevention to engineered resilience
The same shift can be seen in how organisations are approaching technology operations.
Exploited vulnerabilities remain the leading cause of ransomware attacks, yet many incidents still result from delayed patching, inconsistent operational processes or reliance on manual intervention during critical events.
Increasingly, organisations are addressing these challenges through automation.
AI-assisted monitoring, automated patch management, self-healing infrastructure and orchestrated recovery runbooks all contribute to faster, more consistent recovery. Their value extends beyond operational efficiency. They create predictable outcomes during high-pressure situations while generating the evidence needed to demonstrate resilience.
This reflects a broader change in mindset. The most mature organisations are treating resilience as an engineering discipline rather than a compliance programme. Recovery capabilities are designed, automated, tested and continuously improved in the same way as any other critical technology service.
Evidence is replacing assurance
The FCA's first-year observations also highlight an important evolution in governance.
Historically, boards sought assurance that resilience arrangements were in place. Increasingly, they require evidence that those arrangements work.
Examples of good practice include embedding resilience into day-to-day operations, using meaningful resilience metrics and providing effective board oversight. However, regulators also identified recurring weaknesses, including unclear ownership of remediation activities, scenario testing that failed to stretch organisations sufficiently and limited evidence supporting board assurance.
This reflects a wider shift in expectations: from reporting risks to demonstrating outcomes. Governance is no longer measured by the quality of assurance provided to boards, but by the evidence that critical services can be recovered when disruption occurs.
Scenario testing must therefore move beyond compliance exercises. It should replicate severe but plausible events, including cyber-attacks that require systems to be rebuilt from trusted recovery environments. The objective is not simply to complete the exercise but to understand how the organisation performs under pressure and where improvements are required.
This reflects a broader shift in expectations - from reporting risks to demonstrating outcomes.
Resilience extends beyond organisational boundaries
Operational resilience is increasingly shaped by third-party dependencies.
More than 40% of cyber incidents reported to the FCA during 2025 involved third parties, and forthcoming operational incident and third-party reporting requirements will increase scrutiny of supply chain resilience.
Understanding these dependencies is becoming essential. Organisations need to know which critical services rely on external providers, how disruption would affect customers and operations, and whether recovery arrangements have been validated across the wider ecosystem, not just within their own technology estate.
From compliance to capability
The principles of operational resilience remain unchanged: clarity, speed, visibility and continuous learning.
The difference in 2026 is that resilience is no longer judged primarily by the existence of plans, policies or governance frameworks. It is judged by an organisation's ability to recover critical services quickly, consistently and with confidence.
The organisations making the greatest progress are shifting their focus from preventing every possible incident to engineering recoverability into their operations. They are testing recovery as rigorously as they test security controls, automating where consistency matters most and providing boards and regulators with evidence rather than assurance.
Ultimately, operational resilience has become less about proving compliance and more about proving capability.
Recovery is no longer simply the final stage of incident response, it has become the measure by which operational resilience is judged.
Sources
Financial Conduct Authority (FCA), Operational resilience: Insights and observations one year on (March 2026)
Financial Conduct Authority (FCA), PS26/2: Operational incident and third-party reporting (March 2026)
Sophos, The State of Ransomware in Financial Services 2025 (November 2025)